Vulnerability index

Browse CVEs

7,366 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
Unclassified HIGH 8.1
CVE-2025-7667

The Restrict File Access plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1.2. This is due to…

Mitigation only
Fix from $1,950 2025-07-15
Unclassified MEDIUM 5.2
CVE-2025-7379

A security bypass vulnerability allows exploitation via Reverse Tabnabbing, a type of phishing attack where attackers can manipulate the content of t…

Mitigation only
Fix from $1,600 2025-07-09
Unclassified HIGH 8.7
CVE-2025-53540

arduino-esp32 is an Arduino core for the ESP32, ESP32-S2, ESP32-S3, ESP32-C3, ESP32-C6 and ESP32-H2 microcontrollers. Several OTA update examples and…

Patch available
Fix from $1,950 2025-07-07
Online Movie Ticket Booking System MEDIUM 5.4
CVE-2025-7133

A vulnerability classified as problematic has been found in CodeAstro Online Movie Ticket Booking System 1.0. This affects an unknown part. The manip…

No fix yet
Fix from $1,600 2025-07-07
Unclassified HIGH 8.8
CVE-2025-53483

ArchivePage.php, UnarchivePage.php, and VoterEligibilityPage#executeClear() do not validate request methods or CSRF tokens, allowing attackers to tri…

Mitigation only
Fix from $1,950 2025-07-04
Unclassified MEDIUM 6.1
CVE-2025-6041

The yContributors plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.5. This is due to missing …

Mitigation only
Fix from $1,600 2025-07-04
Laundry HIGH 8.8
CVE-2025-52841

Cross-Site Request Forgery (CSRF) vulnerability in Laundry on Linux, MacOS allows to perform an Account Takeover. This issue affects Laundry: 2.3.0.

No fix yet
Fix from $1,950 2025-07-02
Ads Pro HIGH 8.8
CVE-2025-6459

The Ads Pro Plugin - Multi-Purpose WordPress Advertising Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up …

Fix: after 4.89
Fix from $1,950 2025-07-02
Unclassified MEDIUM 5.1
CVE-2025-34050

A cross-site request forgery (CSRF) vulnerability exists in the web interface of AVTECH IP camera, DVR, and NVR devices. An attacker can craft malici…

No fix yet
Fix from $1,600 2025-07-01
Sunshine HIGH 8.8
CVE-2025-53095

Sunshine is a self-hosted game stream host for Moonlight. Prior to version 2025.628.4510, the web UI of Sunshine lacks protection against Cross-Site …

Fix: 2025.628.4510+
Fix from $1,950 2025-07-01
Unclassified HIGH 7.5
CVE-2025-24289

A Cross-Site Request Forgery (CSRF) leading to Cross-Site Scripting (XSS) vulnerability in the UCRM Client Signup Plugin (v1.3.4 and earlier) could a…

Mitigation only
Fix from $1,950 2025-06-29
Medical Card Generation System MEDIUM 6.5
CVE-2025-50369

A Cross-Site Request Forgery (CSRF) vulnerability exists in the Manage Card functionality (/mcgs/admin/manage-card.php) of PHPGurukul Medical Card Ge…

Mitigation only
Fix from $1,600 2025-06-27
Medical Card Generation System MEDIUM 6.5
CVE-2025-50370

A Cross-Site Request Forgery (CSRF) vulnerability exists in the Inquiry Management functionality /mcgs/admin/readenq.php of the Phpgurukul Medical Ca…

Mitigation only
Fix from $1,600 2025-06-27
Unclassified HIGH 7.1
CVE-2025-53332

Cross-Site Request Forgery (CSRF) vulnerability in ethoseo Track Everything track-everything allows Stored XSS.This issue affects Track Everything: f…

Mitigation only
Fix from $1,950 2025-06-27
Unclassified HIGH 7.1
CVE-2025-53338

Cross-Site Request Forgery (CSRF) vulnerability in dor re.place replace allows Stored XSS.This issue affects re.place: from n/a through <= 0.2.1.

Mitigation only
Fix from $1,950 2025-06-27
Unclassified HIGH 7.1
CVE-2025-53329

Cross-Site Request Forgery (CSRF) vulnerability in szajenw Społecznościowa 6 PL 2013 spolecznosciowa-6-pl-2013 allows Stored XSS.This issue affects S…

Mitigation only
Fix from $1,950 2025-06-27
Unclassified HIGH 7.1
CVE-2025-53331

Cross-Site Request Forgery (CSRF) vulnerability in samcharrington RSS Digest rss-digest allows Stored XSS.This issue affects RSS Digest: from n/a thr…

Mitigation only
Fix from $1,950 2025-06-27
Unclassified HIGH 7.1
CVE-2025-53315

Cross-Site Request Forgery (CSRF) vulnerability in alanft Relocate Upload relocate-upload allows Stored XSS.This issue affects Relocate Upload: from …

Mitigation only
Fix from $1,950 2025-06-27
Unclassified HIGH 7.1
CVE-2025-53317

Cross-Site Request Forgery (CSRF) vulnerability in AcmeeDesign WPShapere - WordPress admin theme wpshapere-lite allows Stored XSS.This issue affects …

Mitigation only
Fix from $1,950 2025-06-27
Unclassified HIGH 7.1
CVE-2025-53310

Cross-Site Request Forgery (CSRF) vulnerability in Funnnny HidePost hidepost allows Reflected XSS.This issue affects HidePost: from n/a through <= 2.…

Mitigation only
Fix from $1,950 2025-06-27
Unclassified HIGH 7.1
CVE-2025-53311

Cross-Site Request Forgery (CSRF) vulnerability in Amol Nirmala Waman Navayan Subscribe navayan-subscribe allows Stored XSS.This issue affects Navaya…

Mitigation only
Fix from $1,950 2025-06-27
Unclassified HIGH 7.1
CVE-2025-53312

Cross-Site Request Forgery (CSRF) vulnerability in Looks Awesome OnionBuzz onionbuzz-viral-quiz allows Stored XSS.This issue affects OnionBuzz: from …

Mitigation only
Fix from $1,950 2025-06-27
Unclassified HIGH 7.1
CVE-2025-53313

Cross-Site Request Forgery (CSRF) vulnerability in plumwd Twitch TV Embed Suite twitch-tv-embed-suite allows Stored XSS.This issue affects Twitch TV …

Mitigation only
Fix from $1,950 2025-06-27
Unclassified CRITICAL 9.6
CVE-2025-53314

Cross-Site Request Forgery (CSRF) vulnerability in sh1zen WP Optimizer wp-optimizer allows SQL Injection.This issue affects WP Optimizer: from n/a th…

Mitigation only
Fix from $2,300 2025-06-27
Unclassified HIGH 7.1
CVE-2025-53305

Cross-Site Request Forgery (CSRF) vulnerability in lucidcrew WP Forum Server forum-server allows Stored XSS.This issue affects WP Forum Server: fro…

Mitigation only
Fix from $1,950 2025-06-27
Unclassified HIGH 7.1
CVE-2025-53308

Cross-Site Request Forgery (CSRF) vulnerability in gopi_plus Image Slider With Description image-slider-with-description allows Stored XSS.This issue…

Mitigation only
Fix from $1,950 2025-06-27
Unclassified HIGH 7.1
CVE-2025-53274

Cross-Site Request Forgery (CSRF) vulnerability in Hossin Asaadi WP Permalink Translator wp-permalink-translator allows Stored XSS.This issue affects…

Mitigation only
Fix from $1,950 2025-06-27
Unclassified HIGH 8.8
CVE-2025-53277

Cross-Site Request Forgery (CSRF) vulnerability in Infigo Software IS-theme-companion weblizar-companion allows Object Injection.This issue affects I…

Mitigation only
Fix from $1,950 2025-06-27
Unclassified HIGH 7.1
CVE-2025-53271

Cross-Site Request Forgery (CSRF) vulnerability in Anton Bond Additional Order Filters for WooCommerce additional-order-filters-for-woocommerce allow…

Mitigation only
Fix from $1,950 2025-06-27
Unclassified MEDIUM 5.4
CVE-2025-53262

Cross-Site Request Forgery (CSRF) vulnerability in Writesonic Writesonic writesonic allows Cross Site Request Forgery.This issue affects Writesonic: …

No fix yet
Fix from $1,600 2025-06-27